PT-2024-16395 · Tongda Oa · Tongda Oa

Lvzc

·

Published

2024-10-31

·

Updated

2024-11-04

·

CVE-2024-10598

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tongda OA versions 11.2 through 11.6
Description A critical vulnerability was found in Tongda OA, affecting unknown code of the file general/hr/setting/attendance/leave/data.php of the component Annual Leave Handler. The manipulation leads to improper authorization, allowing remote attacks. The exploit has been disclosed to the public and may be used.
Recommendations For Tongda OA versions 11.2 through 11.6, update to the latest patched version immediately to mitigate risks. As a temporary workaround, consider restricting access to the Annual Leave Handler component until a patch is available. Additionally, audit logs for signs of exploit.

Exploit

Fix

Improper Authorization

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10598

Affected Products

Tongda Oa